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IN THE CLAIMS- 

1 . (cancelled) 



2. (currently amended) The method of claim in notwork data proofing 3ya te . u u j 
reoitod in cla i m 1, farther comprigi np- 

whofoin th& od d rnoii of the bait x i ij not publishing the bait server's 
address to the network, plurality of oliom data prooooaing oyotonw , 

3 . (currently amended) The computer nrno ram product of claim ?n , network data 
procoooine ayut n m n o rocked i n l U uu i 1, wherein th e bait server's address is not published 
to the network, offending nvntem innlnrW mr ,m n,nn r„„ ^ritn p r aC c o 3 in £ r/jt o m. 

4. (currently amended) The system as recit ed in claim 30. network data processing 
s ystem as root ted in olaim 1 7 wherein the bait server's address is not nnhlished to the 
network offotiding ayatem inoluduu tho Jooal .ictrvoft 

5. (cancelled) 

6. (cancelled) 



7. (cancelled) 

8. (cancelled) 

9. (cancelled) 



10. (currently amended) A method for detecting the presence of a computer virus, the 
method comprising; 

receiving, at a bait server, a request to perform a function on the bait server; 
identifying an offending system from which the request originated; 
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alerting a local server that a virus attack is in progress and of the identity of the 
offending system; and 

rtfPot i nc the local ath uilo disconnecting the offending system from the network. 

1 1 - (original) The method as recited in claim 1 0, further comprising: 

prior to disconnecting the offending system, notifying the offending system that it 
is infected with a virus. 

1 2. (original) The method as recited in claim 1 0, further comprising: 
receiving a reconnect request from the offending system; 

verifying that the offending system is disinfected and available to reconnect to the 
network; and 

reconnecting the offending system to the network. 



13. (cancelled) 

14. (cancelled) 

15. (cancelled) 



16. (currently amended) A method in a bait server for detecting the presence of a 
computer virus, the method comprising: 

not publishing th e bait server's address tn a network: 

monitoring the_[[«j] network for the presence of a computer virus; 

responsive to a determination that a virus is detected, determining the identity of 
an offending system within the network from which the virus entered the network; and 

notifying a local server of the nresenre 0 f the virus and the identity of the 
offending system; 

i nstructing all devices within the network tr, W ore all revest, from the nfTmd,^ 
s y stem until the off e ndin K system has been disin f ected and is liable fo r ne tW- 
communicatio n; 
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directing the local server to disconnect the offending system from the network- 
and [[,]] 

responsive to an indication that the «ffr.nrii ng system has h^n disinfected and 
responsive to a reconnect request from the offi n g Svstem tn th« local server. 
reconnecting the offending system to the network 



1 7. (currently amended) The method as recited in claim 1 p_ [[€]], further comprising: 
instructing aU devices within the network to ignore all requests from the offending 

system until the offending system has been disinfected and is available for network 
communication. 

18. (cancelled) 



19. (cancelled) 



20. (original) A computer program product in a computer readable media for use in a 
data processing system for detecting the presence of a computer virus, the computer 
program product comprising; 

first instructions for receiving, at a bait server, a request to perform a function on 
the bait server; 

second instructions for identifying an offending system from which the request 
originated; 

third instructions for alerting a local server that a virus attack is in progress and 
the identity of the offending system; and 

fourth instructions for disconnecting the offending system from a network. 

2 1 . (original) The computer program product as recited in claim 20, further 
comprising: 

fifth instructions for, prior to disconnecting the offending system, notifying the 
offending system that it is infected with a virus. 
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22. (original) The computer program product as recited in claim 20, further 
comprising: 

fifth instructions for receiving a reconnect request from the offending system; 
sixth instructions for verifying that the offending system is disinfected and 
available to reconnect to the network; and 

seventh instructions foT reconnecting the offending system to the network. 

23. (cancelled) 

24. (cancelled) 

25. (cancelled) 

26. (currently amended) A computer program product in a computer readable media 

for use in a data processing system in a bait server for detecting the presence of a 

computer virus, the computer program product comprising: 

first instructions for not publishing the hair ser ver's address published to a 
network; 

second &•* instructions for monitoring the [[a]] network for the presence of a 
computer virus; 

toird seeead instructions, responsive to a determination that a virus is detected, for 
determining the identity of an offending system within the network from which the virus 
entered the network; end 

fourth instructions for notifying a local se rver of the nresance of the vims anH th» 
identity of the offending system^ 

fifth instructions for instructing all de vices within th e network to ignore a l l 
r equests from the offending system until the offendi n g system is au thorized for net™, 
communication; 

sixth thifd-instructions for directing a local server t n H^™~>t r ring jj tne 
offending system from the networ k; and [[rft 
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seventh instructions, resp on sive to an indi c ation that the offending system has 
been disinfected and responsive to a reconnec t request from the offending system to th» 
local server, for reconnecting the offen d ing system to the network. 

27. (currently amended) The computer program product as recited in claim 20 [[€]], 
further comprising: 

fifth_fe«fth-instructions for instructing all devices within the network to ignore all 
requests from the offending system until the offending system is reauthorized for network 
communication. 

28. (cancelled) 

29. (cancelled) 

30. (original) A system for detecting the presence of a computer virus, the system 
comprising; 

a receiver, at a bait server, which receives a request to perform a function on the 
bait server; 

an identifying unit which identifies an offending system from which the request 
originated; 

an virus alert unit which alerts a local server that a virus attack is in progress and 
the identity of the offending system; and 

disconnection unit which disconnects the offending system from a network. 

3 1 . (original) The system as recited in claim 30, further comprising: 

a notification unit which, prior to disconnecting the offending system., notifies the 
offending system that it is infected with a virus. 

32. (original) The system as recited in claim 30, further comprising: 

a reconnect request unit which receives a reconnect request from the offending 

system; 
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a verification unit which verifies that the offending system is authorized to 
reconnect to the network; and 

a reconnecting unit which reconnects the offending system to the network. 

33. (cancelled) 

34. (cancelled) 

35. (cancelled) 

36. (currently amended) A system in a bait server for detecting the presence of a 
computer virus, the system comprising: 

a monitoring unit which monitors a network for the presence of a computer viru^ 
wherein the bait server' s address is not published to the network; 

an identifier which, responsive to a determination that a virus is detected, 
determines the identity of an offending system within the network from which the virus 
entered the network; and 

a notification unit which notifie s a local server of the presence of the virus and the 
identity of the offending system ,; 

a network protection unit which instructs all devices within the network to ignore 
all requests from the offending system u ntil the offending system is reauthorized for 
network communication: and 

a disconnection unit which directs a local server t<> H ienmprt [[ 9 tj the offending 
system from the network. 

a reconnection unit which, responsive to an indication that the offending system 
has been disinfected and responsive to a reconnect request from the offending system to 
the, local server, reconnects the offending system to the network 
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37. (currently amended) The system as recited in claim 30 further comprising: 

a network protection unit which instructs all devices within the network to ignore 

all requests from the offending system until the offending system is reauthorized for 
network communication. 

38. (cancelled) 

39. (cancelled) 
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